IT Cybersecurity Engineer

Postaladdress
Barcelona, Spain
4 days ago
Apply on www.jobleads.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software Applications Software System Penetration Testing Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Continuous Integration DevOps
+12 more
Open Web Application Security Reverse Engineering Software Engineering Software Vulnerability Management Web Applications Google Cloud Cloud Platform System Software Security Mitre Att&ck Cyber Threat Analysis Containerization Serverless Computing

Job description

This position is part of the Product Security Department and is responsible for assessing and improving the security posture of the organization’s products, applications, cloud environments, and enterprise infrastructure through offensive security activities.

The primary responsibility of this position is to identify, validate, and communicate security vulnerabilities before they can be exploited by attackers. The role involves performing penetration tests, security assessments, and adversary simulations across traditional IT environments, cloud platforms, modern applications, and Artificial Intelligence (AI) systems.

The engineer will collaborate with development, infrastructure, cloud, and engineering teams to improve the organization’s overall security posture by providing actionable remediation guidance and security best practices.

  • Plan and execute penetration tests of healthcare products, applications, medical devices, and supporting infrastructure in accordance with defined testing methodologies and project timelines.
  • Perform security assessments of web applications, APIs, desktop applications, embedded systems, cloud environments, and AI-enabled products to identify exploitable vulnerabilities and security weaknesses.
  • Evaluate the security of cloud-native architectures, identity services, and containerized environments supporting healthcare solutions.
  • Assess Artificial Intelligence features and applications for security risks, including prompt injection, unauthorized access, sensitive data exposure, and misuse of AI models.
  • Contribute to the continuous improvement of penetration testing methodologies, tooling, automation, and testing procedures to address emerging technologies and evolving threats.
  • Stay current with the latest offensive security techniques, healthcare cybersecurity threats, cloud technologies, and AI security research to ensure testing methodologies remain effective and aligned with industry best practices.
  • Collaborate with product development and engineering teams to communicate security findings, provide technical guidance, and support secure product development throughout the product lifecycle.
  • Validate the effectiveness of implemented security fixes through remediation verification and follow-up security testing.
  • Produce high-quality technical reports that clearly describe findings, risk levels, exploitation evidence, and practical remediation recommendations for engineering teams., A cybersecurity engineer interacts with different stakeholders including:
  • Software Development teams to coordinate security assessments, communicate technical findings, and support the remediation and validation of identified vulnerabilities.
  • Quality Assurance (QA) teams to integrate penetration testing activities into product release cycles and verify security fixes prior to deployment.
  • Cloud Engineering and DevOps teams to assess cloud infrastructure, containerized environments, CI/CD pipelines, and cloud-native services, providing recommendations to improve security posture.
  • Product Owners (PO) and Product Security Officers (PSO) to define assessment scope, prioritize security risks based on business impact, and support secure product releases.
  • Product Security Architects (PSA) to align penetration testing activities with organizational security strategies, threat models, and vulnerability management processes.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.

Minimum professional experience:

  • 4+ years in Offensive Security, Penetration Testing or Red Teaming.

Experience in several of the following areas:

  • API and Web Application pentesting.
  • Cloud security (AWS, GCP and Azure).
  • Docker and Kubernetes security
  • AI security assessments.
  • Active Directory
  • Reverse Engineering and Binary Exploitation capabilities.

The following work experience and qualifications are a plus:

  • Certifications such as: eJPT, OSCP, CPTS, CRTO, CRTE, or equivalent.
  • Knowledge of security frameworks such as OWASP and MITRE ATT&CK., * Experience in Red Teaming Operations
  • Experience in CTFs in platforms such as Hack The Box
  • Knowledge of relevant standards such as ISO 27001.
  • Knowledge of medical device regulations (FDA, GDPR).
  • Solid knowledge on SW testing process and secure methodology (SSDLC)., * Strong analytical and problem-solving skills to identify, validate, and assess security vulnerabilities and recommend effective remediation strategies.
  • Effective communication skills to convey complex cybersecurity concepts to both technical and non-technical stakeholders.
  • Willingness to stay updated on the latest cybersecurity trends, threats and technologies through continuous learning and professional development.
  • Ability to collaborate with cross-functional teams, share information, and work together to enhance overall cybersecurity posture.
  • Strong interpersonal skills with the ability to build trust, foster teamwork, and contribute positively to a collaborative working environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all